{"id":"DEBIAN-CVE-2014-3566","details":"The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the \"POODLE\" issue.","modified":"2026-09-21T07:00:54.438132268Z","published":"2014-10-15T00:55:02.137Z","upstream":["CVE-2014-3566"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2014-3566"}],"affected":[{"package":{"name":"epiphany-browser","ecosystem":"Debian:12","purl":"pkg:deb/debian/epiphany-browser?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["43.1-1","44.0-1","44.1-1","44.2-1","44.3-1","44.5-1","44.5-2","44.6-1","44~rc-1","45.0-1","45.1-1","45.2-1","45~beta-1","46.0-1","46.0-2","46.1-1","46.2-1","46.3-1","46~alpha-1","46~beta-1","47.0-1","47.2-1","47~beta-1","47~rc-1","48.0-1","48.1-1","48.2-1","48.3-1","48.3-2","48.5-1","48.5-2","48.5-3","48~beta-1","48~rc-1","48~rc-2","49.0-1","49.1-1","49.2-1","49.2-2","49.2-3","50.3-1","50.3-2","50.4-1","50.4-2","51.0-1","51~rc-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"epiphany-browser","ecosystem":"Debian:13","purl":"pkg:deb/debian/epiphany-browser?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["48.3-2","48.5-0+deb13u1","48.5-1","48.5-2","48.5-3","49.0-1","49.1-1","49.2-1","49.2-2","49.2-3","50.3-1","50.3-2","50.4-1","50.4-2","51.0-1","51~rc-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"epiphany-browser","ecosystem":"Debian:14","purl":"pkg:deb/debian/epiphany-browser?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["48.3-2","48.5-1","48.5-2","48.5-3","49.0-1","49.1-1","49.2-1","49.2-2","49.2-3","50.3-1","50.3-2","50.4-1","50.4-2","51.0-1","51~rc-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"erlang","ecosystem":"Debian:12","purl":"pkg:deb/debian/erlang?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:17.3-dfsg-3"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"erlang","ecosystem":"Debian:13","purl":"pkg:deb/debian/erlang?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:17.3-dfsg-3"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"erlang","ecosystem":"Debian:14","purl":"pkg:deb/debian/erlang?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:17.3-dfsg-3"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"gnutls28","ecosystem":"Debian:12","purl":"pkg:deb/debian/gnutls28?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.8-5"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"gnutls28","ecosystem":"Debian:13","purl":"pkg:deb/debian/gnutls28?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.8-5"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"gnutls28","ecosystem":"Debian:14","purl":"pkg:deb/debian/gnutls28?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.8-5"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"haskell-tls","ecosystem":"Debian:12","purl":"pkg:deb/debian/haskell-tls?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.9-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"haskell-tls","ecosystem":"Debian:13","purl":"pkg:deb/debian/haskell-tls?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.9-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"haskell-tls","ecosystem":"Debian:14","purl":"pkg:deb/debian/haskell-tls?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.9-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"lighttpd","ecosystem":"Debian:12","purl":"pkg:deb/debian/lighttpd?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.35-4"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"lighttpd","ecosystem":"Debian:13","purl":"pkg:deb/debian/lighttpd?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.35-4"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"lighttpd","ecosystem":"Debian:14","purl":"pkg:deb/debian/lighttpd?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.35-4"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"netsurf","ecosystem":"Debian:12","purl":"pkg:deb/debian/netsurf?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6-1"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"netsurf","ecosystem":"Debian:13","purl":"pkg:deb/debian/netsurf?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6-1"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"netsurf","ecosystem":"Debian:14","purl":"pkg:deb/debian/netsurf?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6-1"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"nss","ecosystem":"Debian:12","purl":"pkg:deb/debian/nss?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.17.1-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"nss","ecosystem":"Debian:13","purl":"pkg:deb/debian/nss?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.17.1-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"nss","ecosystem":"Debian:14","purl":"pkg:deb/debian/nss?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.17.1-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"openssl","ecosystem":"Debian:12","purl":"pkg:deb/debian/openssl?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.1j-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"openssl","ecosystem":"Debian:13","purl":"pkg:deb/debian/openssl?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.1j-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"openssl","ecosystem":"Debian:14","purl":"pkg:deb/debian/openssl?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.1j-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"pound","ecosystem":"Debian:13","purl":"pkg:deb/debian/pound?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6-6"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"pound","ecosystem":"Debian:14","purl":"pkg:deb/debian/pound?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6-6"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"surf","ecosystem":"Debian:12","purl":"pkg:deb/debian/surf?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.1+git20221016-4","2.1+git20221016-5","2.1+git20221016-6","2.1+git20240324-1","2.1+git20250419-1","2.1+git20250419-2"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"surf","ecosystem":"Debian:13","purl":"pkg:deb/debian/surf?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.1+git20250419-1","2.1+git20250419-2"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"surf","ecosystem":"Debian:14","purl":"pkg:deb/debian/surf?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.1+git20250419-1","2.1+git20250419-2"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"wolfssl","ecosystem":"Debian:12","purl":"pkg:deb/debian/wolfssl?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.8+dfsg-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}},{"package":{"name":"wolfssl","ecosystem":"Debian:13","purl":"pkg:deb/debian/wolfssl?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.8+dfsg-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-3566.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N"}]}